
Skillsoft
Skillsoft is a global leader in corporate learning, providing digital training and education solutions to help businesses improve workforce productivity, reduce risk, and increase innovation.






.webp)
The shared acronym is a coincidence of naming, not of law. Malaysia's Act of 2010 and Singapore's of 2012 were written for different regulatory philosophies and converged only recently, when Malaysia's Amendment Act 2024 closed gaps that had left it behind its neighbour. Operating in both markets means complying with the stricter of each pair, not an average.
| Obligation | Malaysia (PDPA 2010, as amended 2024) | Singapore (PDPA 2012, as amended 2020) |
|---|---|---|
| Regulator | Personal Data Protection Commissioner (JPDP) | Personal Data Protection Commission (PDPC) |
| Breach notification to regulator | As soon as practicable, within 72 hours of becoming aware; written reasons required if late | Within 3 calendar days of assessing the breach is notifiable; assessment itself should complete within 30 days |
| Breach notification to individuals | Within 7 days of notifying the Commissioner, where significant harm is likely | At the same time or after notifying the PDPC, where significant harm is likely |
| Notification threshold | Significant harm — including financial loss, identity theft, reputational damage, loss of access to essential services | Significant harm to any individual, or a breach affecting 500 or more individuals |
| Data Protection Officer | Mandatory from 1 June 2025 for qualifying controllers and processors; notify the Commissioner and publish a DPO email | Mandatory; at least one designated individual, contact details public, registered via the PDPC portal since December 2024 |
| Processor liability | Direct statutory obligations introduced in 2024 — processors must comply with the Security Principle | Organisation remains responsible for data processed on its behalf; processors carry protection and retention duties |
| Cross-border transfer | Permitted; the old whitelist approach replaced by assessment and documentation under the 2025 Cross Border Personal Data Transfer Guidelines | Permitted where the recipient provides a comparable standard of protection to the PDPA |
| Data portability | Right introduced by the 2024 amendments | Provision legislated; not yet in force |
| Maximum penalty | Principle breaches up to RM 1 million and/or 3 years' imprisonment; failure to notify a breach up to RM 250,000 and/or 2 years | Up to 10% of annual Singapore turnover for organisations above SGD 10 million, or SGD 1 million, whichever is higher |
| Personal liability | Directors and managers personally liable unless they show the offence occurred without their knowledge and that they exercised due diligence | Individuals, including directors, can face criminal prosecution for egregious misuse of personal data |
| Breach register | Must be maintained for a minimum of two years | Records expected as part of a documented data protection management programme |
Three rows have direct consequences for how you configure and contract a learning platform, and they are the most commonly overlooked.
The breach clocks are not the vendor's clocks. Malaysia gives you 72 hours from awareness; Singapore three days from assessment. A contract promising notice "promptly" leaves you unable to meet either. The window must be in hours, starting from the vendor's awareness rather than their internal confirmation.
Processor duties change the negotiation. Malaysia's 2024 amendments gave processors direct obligations, so an LMS vendor there has statutory duties of its own, including appointing a DPO. A vendor that cannot name theirs is telling you about its regulatory maturity.
Personal liability changes who cares. Once directors are personally exposed unless they show due diligence, the evidence pack stops being an IT formality and becomes board documentation. Keeping the SOC 2 report, transfer assessment and vendor DPO details on file is the due diligence.
You cannot outsource accountability. You can only outsource the work, and then keep the evidence that you checked it.
A note on sector rules. Base PDPA obligations are the floor, not the ceiling. Bank Negara Malaysia treats cloud adoption as outsourcing under its RMiT policy and expects documented risk assessment, customer data control and cryptographic key management. Financial institutions in both markets, along with healthcare and public-sector bodies, routinely apply residency and access requirements stricter than either PDPA demands. If you are in a regulated sector, start from your regulator's guidance and treat the PDPA as the baseline underneath it. Our overview of learning platforms in banking and financial services covers the additional layer.
Most organisations inventory their HRIS carefully and their LMS barely at all, assuming a training system holds course records and little else. That assumption is why LMS data mapping so often fails an audit. A learning platform sits downstream of the HRIS and accumulates something the HRIS does not have: evidence of what individual employees could not do.
Name, work and sometimes personal email, employee ID, department, cost centre, reporting line, job role, grade, location and joining date — usually synced automatically from the HRIS.
Risk: sync scope is rarely reviewed after go-live; fields nobody needs keep flowingMyKad numbers in Malaysia and NRIC or FIN numbers in Singapore appear whenever certification requires verified identity, or when they are used as login credentials.
Risk: Singapore restricts NRIC collection tightly; using it as a login identifier is a known problemScores, attempts, retakes, failed modules, time taken per question, and the answers themselves. This is performance data with career consequences.
Risk: commonly visible to more managers than intended through default reporting rolesSkill levels, manager assessments, gap analyses and readiness scores — increasingly used in promotion and redeployment decisions.
Risk: treated as analytics rather than as personal data subject to access requestsLogin times, IP addresses, device identifiers, session duration, video watch patterns, and location where mobile apps request it.
Risk: collected by default, rarely disclosed in the privacy notice employees actually sawDiscussion posts, assignment submissions, coaching notes, manager feedback, support tickets and any documents learners upload as evidence.
Risk: unstructured and unclassified, so it escapes retention rules and export requestsHarassment, ethics, whistleblowing and safety training completions — sometimes assigned in response to a specific incident involving that employee.
Risk: remedial assignment history can imply a disciplinary matter to anyone with report accessContractors, channel partners, dealers, franchisees and customers trained on your platform — individuals outside your employment relationship entirely.
Risk: consent basis is often undocumented; these people never signed an employment contractThe sharp edges are the assessment and remedial-training records. A record showing an employee failed a safety assessment three times, or was assigned harassment training in a particular month, is more sensitive in practice than their payroll number — and it leaks through an over-permissive reporting role, not a dramatic external breach.
An HRIS records what someone is. A learning platform records what they could not yet do. The second is often the more damaging disclosure.
Build a one-page data map for your platform. For each category above, record four things: origin system, who sees it in each role, retention period, and whether it appears in the privacy notice employees actually received. Most organisations find two categories they did not know they held and one role with broader visibility than intended.
That map does double duty. It anchors your data protection management programme, and it makes vendor conversations concrete — instead of "is your platform secure?", you can ask whether assessment history can be hidden from line managers while staying visible to compliance, a question with a verifiable answer. Our guide to essential LMS features covers the role and permission model in more depth.
Retention is the cheapest control you are not using. Data you no longer hold cannot be breached or mis-disclosed, and both PDPAs expect personal data to be destroyed or anonymised once its purpose is served. Yet most platforms keep leaver records indefinitely because nobody set a rule. Safety training evidence carries real retention obligations; a 2019 marketing course completion for a 2021 leaver carries none.
This is the question that stalls more procurement cycles than any other, and the honest answer disappoints both camps. Neither statute imposes blanket localisation, so the strict answer is no — a PDPA compliant LMS can lawfully host data outside Malaysia or Singapore. But that is the base law, and the base law is rarely what decides the deployment. Sector regulators, group security policies and customer contracts routinely impose residency requirements the PDPA itself does not.
Malaysia's old whitelist model never worked well in practice. The 2024 amendments replaced it with an assessment framework, elaborated by the Cross Border Personal Data Transfer Guidelines launched in 2025: the controller evaluates whether the destination offers protection comparable to the PDPA, and must produce that assessment on request.
The shift is from permission to justification. Nobody approves your transfer; you make a documented decision and own it. That document is what a regulator asks for after an incident, and "the vendor said it was fine" is not an assessment.
Singapore requires the transferring organisation to ensure the recipient is bound to protection comparable to the PDPA — through contractual terms, binding corporate rules, or a certification the recipient holds. There is no general localisation mandate, which is why Singapore functions as a regional hub. The catch is the word ensure: it is an active obligation, and signing standard terms without checking whether they bind subprocessors does not discharge it.
Neither law asks where your data sits. Both ask whether you can explain, in writing, why sitting there is adequate.
Question five is where surprises concentrate. A vendor may host in Singapore while routing transactional email through a US provider, analytics through a third region and AI content generation through a fourth. Each is a transfer that must appear in your assessment. Our breakdown of how to evaluate an enterprise LMS platform sets out where these questions belong in a structured procurement process.
When in-country hosting genuinely is required. Financial institutions under Bank Negara Malaysia's RMiT policy, healthcare providers handling clinical records, public-sector bodies and government-linked companies, and organisations whose own customer contracts impose residency flow-downs. If you are in one of these categories, make regional hosting a knock-out criterion at shortlist stage rather than discovering at contract stage that your preferred platform cannot meet it.
Every vendor claims enterprise-grade security. The phrase means nothing, so stop evaluating claims and start collecting documents. Eight artefacts, requested together at shortlist stage, separate a serious platform from a well-marketed one faster than any demo — and a vendor's willingness to hand them over tells you as much as their contents.
| Artefact | What it proves | How to read it |
|---|---|---|
| ISO 27001 certificate | A documented information security management system, audited by an accredited body | Check the Statement of Applicability scope covers the LMS product, and that the certificate is current, not expired |
| SOC 2 Type II report | Controls that actually operated over a period, not just existed on paper | Type I is not enough — it is a point-in-time snapshot. Read the exceptions section where auditors record failures; a report with zero exceptions across a year deserves scrutiny, not relief |
| Penetration test summary | Independent adversarial testing within the last twelve months | Ask who performed it, whether it was black or grey box, and — most importantly — whether the findings were remediated and retested |
| Data processing agreement | Contractual allocation of processor duties, transfer terms and breach obligations | Check the breach notice window is in hours from vendor awareness, and that audit rights are real rather than "upon reasonable notice at vendor discretion" |
| Named subprocessor list | Every third party that touches your data, and where each sits | A refusal here is disqualifying. Require advance notice of changes and a right to object |
| Data map and retention schedule | Where every copy lives and how long each is kept | Must cover backups, logs, archives and DR copies — not only the production database |
| Encryption and key management statement | Protection in transit and at rest, and who controls the keys | TLS 1.2 or above in transit, AES-256 at rest is the baseline. Ask whether customer-managed keys are available |
| Incident response plan and DPO contact | That someone is accountable and there is a rehearsed process | In Malaysia, processors must appoint a DPO by law — a vendor that cannot name theirs has a compliance gap of its own |
Most buyers file the report unopened. Four checks extract most of its value.
Scope statement. In the management assertion near the front, it defines which systems were audited. A report scoped to corporate infrastructure but not the LMS product tells you about their laptop policy, not your platform.
Period and type. Type II covers an observation window, commonly six or twelve months; if it ended eighteen months ago the report is stale. Type I means controls were designed, not that they worked.
The exceptions section. Section four lists tests and results, including control failures — the honest part of the document. A small number of exceptions with clear management responses indicates a real audit. Perfect reports are rarer than sales decks suggest.
Complementary user entity controls. Near the end, the report lists controls you own — access reviews, password policy, offboarding. It is the vendor formally naming which parts of security are not theirs, and it is the most-skipped page in the document.
The certificate proves someone checked. The exceptions section proves they checked properly. Read the second one.
Proportionality matters. A 200-person company should not run a defence-contractor procurement. For a small organisation holding routine training records, ISO 27001, a DPA with a defined breach window, a subprocessor list and a data map are a reasonable pack. Scale up to full SOC 2 review and penetration test evidence when learner volume, regulated data or customer flow-downs justify it. Our guidance on choosing the right learning management system covers how to scale diligence to organisational size.
Every vendor claims enterprise-grade security. The phrase means nothing, so stop evaluating claims and start collecting documents. Eight artefacts, requested together at shortlist stage, separate a serious platform from a well-marketed one faster than any demo — and a vendor's willingness to hand them over tells you as much as their contents.
| Artefact | What it proves | How to read it |
|---|---|---|
| ISO 27001 certificate | A documented information security management system, audited by an accredited body | Check the Statement of Applicability scope covers the LMS product, and that the certificate is current, not expired |
| SOC 2 Type II report | Controls that actually operated over a period, not just existed on paper | Type I is not enough — it is a point-in-time snapshot. Read the exceptions section where auditors record failures; a report with zero exceptions across a year deserves scrutiny, not relief |
| Penetration test summary | Independent adversarial testing within the last twelve months | Ask who performed it, whether it was black or grey box, and — most importantly — whether the findings were remediated and retested |
| Data processing agreement | Contractual allocation of processor duties, transfer terms and breach obligations | Check the breach notice window is in hours from vendor awareness, and that audit rights are real rather than "upon reasonable notice at vendor discretion" |
| Named subprocessor list | Every third party that touches your data, and where each sits | A refusal here is disqualifying. Require advance notice of changes and a right to object |
| Data map and retention schedule | Where every copy lives and how long each is kept | Must cover backups, logs, archives and DR copies — not only the production database |
| Encryption and key management statement | Protection in transit and at rest, and who controls the keys | TLS 1.2 or above in transit, AES-256 at rest is the baseline. Ask whether customer-managed keys are available |
| Incident response plan and DPO contact | That someone is accountable and there is a rehearsed process | In Malaysia, processors must appoint a DPO by law — a vendor that cannot name theirs has a compliance gap of its own |
Most buyers file the report unopened. Four checks extract most of its value.
Scope statement. In the management assertion near the front, it defines which systems were audited. A report scoped to corporate infrastructure but not the LMS product tells you about their laptop policy, not your platform.
Period and type. Type II covers an observation window, commonly six or twelve months; if it ended eighteen months ago the report is stale. Type I means controls were designed, not that they worked.
The exceptions section. Section four lists tests and results, including control failures — the honest part of the document. A small number of exceptions with clear management responses indicates a real audit. Perfect reports are rarer than sales decks suggest.
Complementary user entity controls. Near the end, the report lists controls you own — access reviews, password policy, offboarding. It is the vendor formally naming which parts of security are not theirs, and it is the most-skipped page in the document.
The certificate proves someone checked. The exceptions section proves they checked properly. Read the second one.
Proportionality matters. A 200-person company should not run a defence-contractor procurement. For a small organisation holding routine training records, ISO 27001, a DPA with a defined breach window, a subprocessor list and a data map are a reasonable pack. Scale up to full SOC 2 review and penetration test evidence when learner volume, regulated data or customer flow-downs justify it. Our guidance on choosing the right learning management system covers how to scale diligence to organisational size.
Sophisticated attacks make headlines but cause few incidents in a PDPA compliant LMS deployment. The pattern across enforcement decisions and cloud advisories is mundane: defaults left in place, permissions never reviewed, accounts never closed. MyCERT's advisories on Malaysian cloud environments name misconfiguration, over-privileged accounts and insecure API keys — not zero-days.
The most common and least dramatic failure. A "manager" role created once during implementation gets visibility of assessment results, failure history and remedial assignments across a whole business unit rather than a direct team. Nobody notices because nothing breaks.
Fix: review every role's data scope at go-live and every six months after; test by logging in as each role rather than reading the permission matrixWhere deprovisioning is manual rather than HRIS-driven, departed employees keep access for weeks. Contractors and channel partners are worse — often never in the HRIS at all, so no automated offboarding trigger exists.
Fix: automated joiner-mover-leaver provisioning from the HRIS, plus a scheduled orphan-account report for anyone outside itAn integration configured once to pull "the employee record" quietly transfers salary band, home address, emergency contact or national identity number into a system with no use for them. Every extra field is breach exposure for zero functional benefit.
Fix: field-level mapping reviewed against actual platform requirements; default to excluding a field unless a named feature needs itEvery control ends the moment an administrator downloads a completion report and emails it. That file now sits in an inbox, a shared drive and a personal laptop, outside every access control and retention rule you configured.
Fix: restrict bulk export to named roles, log every export, and provide in-platform dashboards good enough that people stop needing spreadsheetsCommon where a kiosk or shared tablet serves a whole shift. It destroys attribution — you cannot tell who accessed what — and one credential unlocks records for dozens of people.
Fix: individual identity even without corporate email, using employee ID or phone-number login with a short session timeout on shared devicesSupport engineers often hold standing production access, sometimes from jurisdictions outside your transfer assessment. Standing access is the problem: an hour-long ticket does not justify permanent visibility.
Fix: require just-in-time, time-boxed, customer-approved and fully logged support access, and ask for the access log during a quarterly reviewStaging and UAT environments get populated with a production copy so testing feels realistic, then secured to a lower standard, excluded from monitoring and forgotten — often in a different region than your residency assessment covered.
Fix: mandate anonymised or synthetic test data contractually, and include non-production environments in your data mapRisks two, four and seven share a root: they happen after go-live, once the project team disbands and nobody owns the security posture. That is an operating-model gap, not a technology gap, and no certification protects against it. Assign a named owner for access review before the implementation team dissolves — our guidance on LMS implementation strategy covers where that handover belongs in the rollout plan.
The uncomfortable comparison. Organisations weighing cloud against on-premise usually assume self-hosting is safer. In practice, an on-premise LMS depends on a small internal team to patch, monitor, encrypt backups, manage keys and run penetration tests — all of which a reputable cloud vendor does as its core business under external audit. Self-hosting's real advantage is control over jurisdiction and access, which matters enormously in regulated sectors and much less elsewhere.
Security controls fail occasionally; contracts decide what happens when they do. These seven clauses are where regional deployments most often turn out under-protected, and all seven are easier to negotiate during the sales cycle than at renewal.
The vendor must notify you within a defined number of hours of becoming aware of an incident — not of confirming it or completing an investigation. Twenty-four hours is reasonable; longer erodes your own 72-hour and three-day windows.
Red flag: "promptly", "without undue delay", or a clock starting at the vendor's internal confirmationA current list annexed to the agreement, advance notice of changes, and a right to object with a termination remedy. This is how your transfer assessment stays accurate over time rather than only on day one.
Red flag: a general permission to appoint subprocessors with notice given only on a webpageThe clause must specify production, backups, logs, archives and disaster recovery, and commit the vendor to notice before any change. A promise about "hosting" alone leaves every derivative copy unaddressed.
Red flag: residency stated in a sales deck or a support article rather than in the contractThe right to request current certifications annually, receive completed security questionnaires, and audit on reasonable notice where a regulator requires it. Most vendors offer report access instead of an on-site audit, which is usually acceptable if the reports are current.
Red flag: audit permitted only "at the vendor's sole discretion" or at your full cost regardless of findingsWhat you receive, in which formats, within how many days, at what cost — plus certified deletion of all copies including backups. Learner records, assessment history, SCORM and xAPI packages and completion evidence should all be named.
Red flag: export available only during the subscription term, or extraction charged as a professional services projectStandard SaaS caps are often twelve months of fees or lower, sometimes one month. Against a Singapore penalty of up to 10% of local turnover, that allocates almost all the risk to you. Data protection breaches should sit outside the general cap or under a much higher one.
Red flag: a single aggregate cap covering everything including data protection and confidentialityWhether vendor personnel can access production data, from which jurisdictions, under what approval, for how long, and with what logging available to you. This clause keeps your residency position honest once the platform is live.
Red flag: silence on the subject, which in practice means standing global accessA liability cap set at one month of fees is not a risk allocation. It is a statement that the risk is entirely yours.
Ask for the standard data processing agreement before commercial negotiation begins. Three things become visible: whether one exists, whether it was written for this region or lifted from a European template referencing regulations neither market applies, and how fast it arrives. A mature vendor sends it the same day because it is a standing document; one that takes two weeks is drafting it.
The same test works for the subprocessor list and DPO contact. None require legal review to request, and response time alone is diagnostic. For the wider platform context these clauses sit inside — what a business-grade system should include before you start negotiating terms — see our guide to what a corporate LMS is.
Skills Caravan serves enterprises across India, Singapore, Malaysia, the UAE, Kuwait and Oman, so these questions come up in procurement most weeks. Rather than restate marketing claims, here is our position on each control area above — including where a different vendor may suit you better.
Assessment history, failure records and competency ratings can be scoped separately from completion data, so compliance teams see what they need without exposing performance records to every line manager.
Employee ID or phone-number login for frontline and shared-device settings, with individual attribution preserved — avoiding the generic-login problem that breaks audit trails.
Automated joiner-mover-leaver sync with field-by-field mapping, so leaver accounts close on the HR event and unnecessary fields never enter the platform.
Contractors, channel partners and dealers get a governed enrolment and offboarding path of their own, which is where orphan accounts usually accumulate.
Bulk export restricted to named roles and logged, with in-platform dashboards designed to reduce the spreadsheet habit that moves data outside every control.
Statutory and safety evidence retained to its obligation; routine completion data aged out on schedule, rather than everything accumulating indefinitely by default.
Posture is easier to maintain when visible. Below is the governance view an administrator or DPO works from — metrics showing whether controls are holding now, not whether they were configured correctly once.
The bottom two rows are the honest part. Most platforms, ours included, can be configured correctly and then drift, because permission re-certification is a recurring task nobody enjoys. Surfacing the drift is what makes it fixable. Explore the architecture on our learning experience platform page, or how these controls apply to regulated programmes on our compliance training software page.
Ask us the same questions you ask everyone else. The eight-artefact pack is not a test we would rather avoid — it is one we would rather every buyer in this region applied uniformly, because it rewards vendors who have done the work. If any vendor, including us, cannot produce those documents, that is your answer.
Selecting a well-secured platform is about a third of the work. The rest is configuring it correctly, documenting the decisions, and stopping the configuration from drifting once the project team disperses. This eight-step sequence covers a typical deployment across both markets.
| Cadence | Task | Why it matters |
|---|---|---|
| Monthly | Orphan account report — anyone active without a matching HR record | Catches contractors and partners who have no automated leaver trigger |
| Quarterly | Bulk export log review; vendor support access log request | Both are where data quietly leaves your control perimeter |
| Half-yearly | Role permission re-certification, tested by logging in as each role | Permission scope drifts as new roles are cloned from old ones |
| Annually | Refresh vendor certifications, subprocessor list and transfer assessment | SOC 2 reports expire; subprocessor lists change without anyone reading the notice |
| Annually | Retention run — delete or anonymise records past their purpose | Data you no longer hold cannot be breached or requested |
| On change | Re-assess when the vendor changes hosting region or adds a subprocessor | Your filed transfer assessment becomes inaccurate the moment either changes |
The Malaysian 72-hour and Singaporean three-day clocks are short, and they run while people are still working out what happened. A one-hour tabletop exercise once a year — say, "the vendor reports unauthorised access to a database holding assessment records for 4,000 learners" — exposes the gaps that matter: who decides the threshold is met, who drafts the notification, who contacts the vendor, and who signs off.
Malaysia also requires a breach register kept for at least two years, so the paperwork is not optional even for incidents that prove non-notifiable. Build the template during the exercise, not during the incident. If compliance programmes sit in the same governance remit, our guide to developing a compliance training strategy covers how data protection awareness fits alongside the rest of the mandatory curriculum.
The step teams skip. Step six — testing role visibility by logging in — takes an afternoon and prevents the most common category of incident described here. It gets skipped because the permission matrix looks correct on paper. The matrix describes intent; a test account describes reality, and they diverge more often than anyone expects.
Every failure below has happened to organisations that bought a genuinely secure PDPA compliant LMS and undid the benefit through process rather than technology. None requires an attacker.
ISO 27001 and SOC 2 describe the vendor's controls. They say nothing about your role configuration, export habits or leaver process — where most incidents originate. The certificate starts your diligence rather than concluding it.
Accountability does not transfer with the hosting. Indemnities allocate money between the parties; they do not move your name off the enforcement decision or protect directors from personal exposure under Malaysia's amended Act.
Different clocks, thresholds, transfer mechanisms and penalty structures. Operating in both markets means meeting the stricter obligation in each pair, not designing to an average.
Contractors, dealers, partners and customers on your platform are data subjects with no employment relationship supplying a lawful basis, and usually no automated offboarding — the least governed and fastest-growing learner population in most deployments.
Roles get cloned, scopes widen, accounts accumulate, retention never runs. Configured correctly in month one, the platform has diverged quietly ever since because no named person owns the review.
Return format, timeline, cost and certified deletion are cheap to agree during the sales cycle and nearly impossible to improve later. By renewal, migration difficulty has become the vendor's leverage.
A cloud based learning management system is not inherently riskier than a server in your own building — for most organisations it is measurably safer, because a specialist vendor patches, monitors and audits at a standard a small internal team cannot sustain. The real risks are jurisdictional and operational: who can reach the data, from where, under whose law, and whether anyone is still checking six months after launch.
So the title question has a practical form. Not "is the cloud safe?" but "can this vendor produce a SOC 2 report, a named subprocessor list, a data map covering backups, and a breach notice window short enough for a 72-hour clock — and can I show a regulator that I asked?" If yes, your data is as safe as it reasonably can be. If a vendor cannot produce those documents, you already have your answer.
If you are still mapping the platform categories underneath this decision, our explainers on what a learning management system is and what an LXP adds cover the ground before the security questions begin.
Bring the eight-artefact list to the call. We will walk through hosting regions, subprocessors, our DPA and breach notice terms against your Malaysian or Singaporean obligations — and say plainly if a requirement is one we cannot meet.
Zainab is an experienced LearnTech leader with a strong track record of building and scaling digital learning solutions across the Middle East, Africa, APAC, the UK, and the USA. With deep expertise in Generative AI, capability development, and data-driven learning strategies, she has helped organizations modernize their learning ecosystems, enhance employee readiness, and deliver impactful, scalable L&D outcomes. Her work blends innovation with strategic clarity, enabling enterprises to adopt future-ready learning models that drive sustainable growth.
See how enterprises close skill gaps with AI. We'll email your brochure instantly.
Please enter your name, a valid email, and your phone number.
We respect your privacy. No spam — unsubscribe anytime.
Your platform overview is on its way. You can also download it right now.
Download Brochure











.png)
.png)
.png)
%20(1).png)
.png)







.webp)











.png)
.png)
.png)
%20(1).png)
.png)















Skillsoft is a global leader in corporate learning, providing digital training and education solutions to help businesses improve workforce productivity, reduce risk, and increase innovation.

FinShiksha provides a practical and industry-relevant approach to finance education, with courses designed by industry experts and delivered through interactive and engaging methods.

Wall Street Prep offers best-in-class financial training for aspiring finance professionals and corporate clients.

Udemy Business offers an unparalleled learning experience for organizations looking to upskill their workforce with over 155,000 courses taught by expert instructors.







.webp)








